As per sources, a critical security flaw has been discovered in Microsoft’s OneDrive File Picker that could allow websites to access a user’s entire cloud storage instead of just the files selected for upload. According to the Oasis Research Team, the issue arises from overly broad OAuth scopes and misleading consent prompts, which fail to clearly communicate the extent of access being granted. This vulnerability may impact several third-party applications integrated with OneDrive, including ChatGPT, Slack, Trello, and ClickUp. The flaw stems from the File Picker requesting full read access to a user’s drive, even when only a single file is being uploaded. This is due to the absence of fine-grained OAuth scopes within OneDrive. Users are presented with vague consent prompts, making it difficult to differentiate between legitimate apps and potentially malicious ones, both of which are forced to request excessive permissions. Oasis further reported that OAuth tokens are often stored insecurely in browser session storage in plaintext format. In some cases, refresh tokens are also issued, granting long-term access without requiring users to re-authenticate. This combination significantly increases the risk of unauthorized access and potential data breaches. Microsoft has acknowledged the issue following responsible disclosure but has yet to release a fix. In the meantime, it is recommended to disable OneDrive file uploads via OAuth where possible, avoid using refresh tokens, securely store access tokens, and remove them once they are no longer needed. Organizations should implement regular security audits and closely monitor OAuth permissions to safeguard sensitive user data.
There were identified several security flaws in BitLocker, the Windows disk encryption module, that would potentially allow attackers to get unauthorized access to the protected in...
According to Okta, the cybersecurity attacks have been reported against their IAM systems. The malicious actors were trying to employ credential-based methods to breach the corpora...
Agentic AI-powered browsers are reshaping how users interact with the internet by automating tasks like summarizing content, managing emails, and navigating across sites. While thi...